DiG DNS Lookup
Query DNS records directly from the domain's authoritative server to see up-to-date information.
Fast Query
Records come straight from the domain's authoritative server, so you see the current record instead of an old cached one.
10 Record Types
Supports A, AAAA, CNAME, MX, NS, TXT, SOA, PTR, SRV, and CAA record types.
Detailed Result
View TTL, Authority, and answer records in detail.
What is DiG?
DiG (Domain Information Groper) is a command-line tool for querying DNS records. This page does the same in your browser: it shows a domain's A, AAAA, CNAME, MX, NS, TXT, SOA, PTR, SRV and CAA records together with their TTL values.
The query goes to the domain's authoritative DNS server, and the server that answered is shown in the result. This way you see the current record instead of an old one cached by public DNS servers. If the authoritative servers cannot be reached, the query goes through Cloudflare and the result is marked as possibly cached.
How to use
- 1Enter the domain and choose the record type.
- 2Press Query.
- 3Review the records, their TTL values and the server that answered.
Frequently asked questions
What are the DNS record types for?
An A record points a domain to an IPv4 address, an AAAA record to an IPv6 address. CNAME points one name to another, MX decides which server receives email, and TXT carries text such as SPF and verification codes. NS records show which DNS servers manage the domain.
What is TTL?
TTL (Time To Live) is how many seconds a record is kept in DNS server caches. If the TTL is 3600, for example, some users may keep seeing the old record for up to an hour after it changes.
The record looks up to date here, so why does my site still go to the old address?
This page asks the authoritative server, so it shows the change immediately. The DNS server your connection uses may keep the old record cached until its TTL runs out. You can see which servers already have the change with the DNS Propagation tool.
What is a CAA record?
A CAA record specifies which certificate authorities may issue SSL certificates for your domain. If a CAA record only allows Let's Encrypt, for example, no other authority can issue a certificate for that domain.
How do I run the same query on the command line?
dig example.com A asks the DNS server your computer uses. To ask the authoritative server, first find the nameserver with dig NS example.com, then query it directly with dig @ns1.example.com example.com A.